- How to setup BurpSuite and SSL pinning for dynamic analysis.
- A checklist for mobile app pentest. Contains both Android and IOS. It's actually much more than a checklist. Fell free to have a look.
- When analysing static applications, you can come across API keys, especially Google API keys. This is a resource to help you check these keys.
- Cheatsheet for commands
- A resource on tampering with Android Cordova apps.
- A tool that helped me during certain situation. It is an HTTP proxy interceptor to analyse HTTP requests and responses.